Senior Security Governance and Risk Consultant
Há 3 horas
Our Company
Tenchi is a Cyber Security company building innovative technology focused on Third-Party Cyber Risk Management for businesses. Founded by serial entrepreneurs and supported by solid institutional investors, we are driven to disrupt this fast-growing industry.
Tenchi was created to tackle a real challenge: companies often face security risks because their third-parties don't maintain the same level of cyber protection. This gap leaves even the largest organizations potentially vulnerable to incidents they can't directly control. That's exactly where we step in.
Our TPCRM SaaS solution, Zanshin, is the only global TPCRM solution that offers both inside-out and outside-in visibility - combining external attack surface monitoring with automated, continuous, and non-intrusive assessments of cloud infrastructure (IaaS, PaaS, SaaS) and security controls.
Our People and CultureAt Tenchi, we build innovative technology to help companies secure their ecosystems with transparency and peace of mind. We are ambitious and purpose-driven. Our culture is rooted in intentionality, transparency, and action. We move fast, communicate openly, and invest in people who want to make an impact.
As a 100% remote company with team members across Brazil, the US, Canada, Argentina, and Spain, we embrace flexibility while solving meaningful challenges together.
Want to know more about our DNA? Watch the video.
What will you do?- Lead the planning, execution, and delivery of security governance and risk management projects for clients across various industries;
- Conduct security maturity assessments based on established frameworks (e.g., NIST CSF, CIS Controls, ISO/IEC 27001), and identify gaps, risks, and areas for improvement;
- Design, implement, and maintain Information Security Management Systems (ISMS) in compliance with ISO 27001 or other relevant standards;
- Develop and manage Information Security Master Plans (PDSI), aligning security strategy with business objectives;
- Execute Third Party Cyber Risk Management (TPCRM) processes, including due diligence assessments, vendor risk scoring, and remediation planning;
- Lead or support cybersecurity audits and regulatory compliance reviews (e.g., LGPD, GDPR, SOX);
- Provide guidance and recommendations to clients on risk mitigation strategies, security policies, procedures, and controls;
- Collaborate with cross-functional teams (Legal, IT, Compliance, Procurement, etc.) to embed security governance into broader business processes;
- Conduct occasional on-site visits to clients or third parties as required by project needs;
- Deliver executive-level reporting and presentations on risk posture, findings, and strategic recommendations;
- Mentor junior consultants and support internal capability development within the GRC team;
- Stay up to date with emerging threats, regulatory changes, and industry trends to continuously enhance client value and service delivery.
What we're looking for?
- Deep understanding of security frameworks, regulations, and cybersecurity compliance requirements (e.g., NIST, CIS, ISO/IEC 27000);
- Proven track record of leading and delivering complex security projects with direct client interaction;
- Experience with risk assessment tools and methodologies is a plus;
- Strong analytical, organizational, and problem-solving skills;
- Excellent interpersonal and communication abilities, with the capability to convey complex topics in a clear and concise manner;
- Certifications such as CISSP, CISM, CRISC, or similar are strongly preferred;
- Comfortable working in remote environments while maintaining high engagement and collaboration with clients and teams.
- Fluency in Portuguese and English.
-
São Paulo, Brasil Tenchi Security Tempo inteiroOur Company Tenchi is a Cyber Security company building innovative technology focused on Third-Party Cyber Risk Management for businesses. Founded by serial entrepreneurs and supported by solid institutional investors, we are driven to disrupt this fast-growing industry. Tenchi was created to tackle a real challenge: companies often face security risks...
-
Sao Paulo, Brasil Control Risks Tempo inteiroBased in São Paulo, the Consultant will assist on the day-to-day delivery of security services to Control Risks’ clients primarily in Brazil, as well as further afield as required. The Consultant will provide consultancy advice and training to clients, primarily in the area of security service, as well as organizing, managing and coordinating...
-
Security Risk Management Specialist
1 semana atrás
São Paulo, Brasil Canonical Tempo inteiroOverview In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do. To...
-
ERM & Risk Governance Specialist
2 semanas atrás
São Paulo, São Paulo, Brasil Nubank Tempo inteiro R$120.000 - R$180.000 por anoAbout UsNu is one of the largest digital financial platforms in the world, with more than 122 million customers across Brazil, Mexico, and Colombia. Guided by our mission to fight complexity and empower people, we are redefining financial services in Latin America and this is still just the beginning of the purple future we're building.Listed on the New York...
-
Tech Risk and Controls Lead
Há 2 dias
São Paulo, Brasil JPMorganChase Tempo inteiroOur Infrastructure Platform group is filled with innovators who love technology as much as you do. Together, you will use a disciplined, innovative and a business focused approach to develop a wide variety of high-quality products and solutions. You will work in a stable, resilient and secure operating environment where you and the services you deliver will...
-
ERM & Risk Governance Specialist
2 semanas atrás
São Paulo, São Paulo, Brasil Nubank Tempo inteiro R$80.000 - R$120.000 por anoAbout UsNu was born in 2013 with the mission to fight complexity to empower people in their daily lives by reinventing financial services. We are one of the world's largest digital banking platforms, serving millions of customers across Brazil, Mexico, and Colombia. For more information, visit our institutional page About the Team:Nubank is seeking a dynamic...
-
Governance, Risk, and Compliance
Há 7 dias
São Paulo, Brasil Tata Consultancy Services Tempo inteiroGet AI-powered advice on this job and more exclusive features. Direct message the job poster from Tata Consultancy Services Come to one of the biggest IT Services companies in the world! Here you can transform your career! Why to join TCS? Here at TCS we believe that people make the difference, that's why we live a culture of unlimited learning full of...
-
Governance, Risk, and Compliance
Há 7 dias
São Paulo, Brasil Tata Consultancy Services Tempo inteiroGet AI-powered advice on this job and more exclusive features. Direct message the job poster from Tata Consultancy Services Come to one of the biggest IT Services companies in the world! Here you can transform your career! Why to join TCS? Here at TCS we believe that people make the difference, that's why we live a culture of unlimited learning full of...
-
São Paulo, Brasil Kyndryl Tempo inteiro**Who We Are** At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. **The...
-
Technical Solutions Consultant
Há 7 dias
State of São Paulo, Brasil beBeeIdentity Tempo inteiroJob Overview We are seeking a highly skilled Technical Solutions Consultant to join our team in Latin America. This is an exciting opportunity for someone to champion the value of Identity Governance and Administration (IGA) while mastering our software solutions. Key Responsibilities Collaborate with sales teams to create, move, and close pipeline...